Ubuntu alert USN-8349-1 (rsync)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8349-1] rsync vulnerabilities | |
| Date: | Mon, 01 Jun 2026 10:56:14 +0000 | |
| Message-ID: | <E1wU0Ja-0000pv-5X@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8349-1 June 01, 2026 rsync vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in rsync. Software Description: - rsync: fast, versatile, remote (and local) file-copying tool Details: Calum Hutton discovered that rsync contained a heap-based out-of-bounds read when handling file transfers. A remote attacker with read access to an rsync server could possibly use this issue to cause a denial of service. (CVE-2025-10158) Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that rsync daemons configured without chroot protection were exposed to a race condition on parent path components. A local attacker with write access to a module could possibly use this issue to overwrite files, obtain sensitive information, or escalate privileges. (CVE-2026-29518) It was discovered that rsync did not properly validate a length value while sorting extended attributes. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41035) It was discovered that rsync performed reverse-DNS lookups after chrooting in some daemon configurations. A remote attacker could possibly use this issue to bypass hostname-based access controls and access network services. (CVE-2026-43617) Omar Elsayed discovered that rsync did not properly check for integer overflows while decoding compressed tokens. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-43618) Andrew Tridgell discovered that rsync did not fully fix a symlink race condition in path-based system calls for daemons configured without chroot protection. A local attacker could possibly use this issue to overwrite files, obtain sensitive information, or escalate privileges. (CVE-2026-43619) Pratham Gupta discovered that rsync did not properly validate an index while processing file lists. A remote attacker could possibly use this issue to cause rsync to crash, resulting in a denial of service. (CVE-2026-43620) Michal Ruprich discovered that rsync contained an off-by-one error while handling HTTP proxy responses. An attacker able to intercept network communications or a malicious proxy server could possibly use this issue to cause a denial of service. (CVE-2026-45232) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS rsync 3.1.3-8ubuntu0.9+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS rsync 3.1.2-2.1ubuntu1.6+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS rsync 3.1.1-3ubuntu1.3+esm5 Available with Ubuntu Pro Ubuntu 14.04 LTS rsync 3.1.0-2ubuntu0.4+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. After a standard system update you need to restart rsync daemons if configured to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8349-1 CVE-2025-10158, CVE-2026-29518, CVE-2026-41035, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmodZHwACgkQcpJm3tlz hgERiw//f8EL7+N2+d2lNF6plWENw/VheSayPBO4Jq/OWccrRO+7kcYUagWzVhsa n9GPl+oE0JKUh3Ul9lqSAVb8SOilGhKQr4HMryu1g2V/xsnnhFlnqkjrJ/nbUUTE hh2LEp1l7y9KeQX1WETA18YVFwj40obzQcRtHEGmyLFiTLtbvrwlVTB0wT7Frf7P i4IjA7M3JRwMVJAflUGO3xRV2IdLX2n5YHhPFxgkxQgVOhnxS80QwfShvccCuI+B Zhp7P7jJDMlqrE2dKn0IOpV/zC7bXlJVfqYpGV7BoJa0g3mQeg/KzvUWPrkx50Tq AOfznKVP21rh+KHh+oGI0Kngf3fDVqhlztg478Tezb+JrC6fk61VUEa7kw49/LD8 JyrieAbaLP1Y1MdUWroY+E3sRvGfppFzAaoq1oxDWTWpRog5nepfitccE48/fHqp jsjbrdP53zmwQ3bxur0tPU95nHOJFM1hnmII0EVkQKseE4bOQ6XIJaM9utmAnlpS BmhRNf/e5uKdWy0uUHCgR1/9CzzXQaanY8159NjEt1ne0x2adcJejNle0UyYj9eu GCRhxtCt9HK3X0Fh2e91b+4nGfK08jY7KjLdOfqEeN0flpRX6FrxvTA09yGXWIck SWh0AFbE+n+HOyGTrLBoAEZHT6yyGr/yuEUAE5/cQ5DSGG5j9DM= =LWDT -----END PGP SIGNATURE-----
